Solved

Active Directory  - File Shares User Rights

Posted on 2013-01-04
9
562 Views
Last Modified: 2013-01-07
Hi,

we have a "File Server" running on windows server 2003 R2 in our domain with 1,2 TB of user data... :)
With over thousands of folders and subfolders. And right now we have no way of knowing which user have what right to what folder (or subfolder)...
My question is, is there any kind of program, script, or some another way to see which user has what right to a folder on that server?
For example, we have folder "Production" with 10 subfolders, and we want to know what right does a user "John" have for that folder and subfolders.

Hope somebody knows how to solve this cause I am out of ideas :)
Thanks
0
Comment
Question by:Sebastianpervan
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 3

Expert Comment

by:gaurav2rawat
ID: 38743467
You could use ad ntfs permissions analyzer which gives all the shared and ntfs permission
her is the link, good luck.

http://www.solarwinds.com/products/freetools/permissions_analyzer_for_active_directory/
0
 

Author Comment

by:Sebastianpervan
ID: 38743492
Hi gaurav2rawat,

thanks for the suggestion, I actually already tried it, but unfortunately is only shows permissions for one folder (that you choose) not the subfolders in it.

I am really stuck on this one... :/
Because I would like to list for all the the users all the folders that they can access. And then to see which users have too much rights and acess.
0
 
LVL 3

Expert Comment

by:gaurav2rawat
ID: 38743510
Hello

You'll have to manually check it for all the folders as even other tools that are available doesn't really tells the permission for subfolders. You could try AD Manager plus but I doubt even that'll provide such granularity.
0
Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 
LVL 26

Accepted Solution

by:
Leon Fester earned 350 total points
ID: 38743538
Our auditors frequently use dumpsec to get permissions from servers:
http://www.systemtools.com/somarsoft/?somarsoft.com

Another tool from Microsoft is Calcs:
http://ss64.com/nt/cacls.html
0
 
LVL 26

Expert Comment

by:Pber
ID: 38743749
A free tool might be tough.  As dvt_localboy mentioned auditors typically use dumpsec and troll through the output.

At one time we used this: http://www.quest.com/enterprisesecurityreporter/ (it was still Scriptlogic at the time).  It will collect all your security from all your folders/files, etc and place them in a database that can then be queried any which way you like.  We used it for duplicate group cleanup.
0
 

Author Comment

by:Sebastianpervan
ID: 38743801
Thank You all for your replies, I will test these applications in these few days and get back to you!
:)

Regards,
Sebastian
0
 
LVL 26

Expert Comment

by:Leon Fester
ID: 38743884
Last time I checked, dumpsec was free and pretty easy to use.
It has many builtin queries and reports, available at a click.
0
 
LVL 11

Assisted Solution

by:Venugopal N
Venugopal N earned 150 total points
ID: 38744322
Also you can use Varonis from which you can generate the report for all kind of needs.Also varonis it provides automated unstructured data protection and management ( i.e.., the data access can be managed by the data owners itself).But the hard part is it not free of cost.
0
 

Author Closing Comment

by:Sebastianpervan
ID: 38750029
Thanks everyone for the help, I've distributed points based on the speed of the posts and applications cost :)
Both application will do the trick!

Thanks,
Sebastian
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question